296,733
Total vulnerabilities in the database
XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during unmarshalling, leading to a remote application crash, as demonstrated by an xstream.fromXML("<void/>") call.
| Software | From | Fixed in |
|---|---|---|
| debian / debian_linux | 8.0 | 8.0.x |
| debian / debian_linux | 9.0 | 9.0.x |
com.thoughtworks.xstream / xstream
|
- | 1.4.10 |
| redhat / jboss_middleware | 1 | 1.x |
| redhat / fuse | 1.0 | 1.0.x |
| xstream / xstream | - | 1.4.9.x |